I’ve received an email asking me to install a security patch
The message looks like an official alert, it names a vulnerability and offers a file to install: this is exactly the scenario of a documented campaign against WooCommerce merchants, and the “patch” is the hack itself.
What the message claims, and why it is false
The scenario is documented. On 23 April 2025, Patchstack published its analysis of an email campaign imitating an official WooCommerce security alert. The message announces a flaw called “Unauthenticated Administrative Access”, states that your shop is affected, and invites you to download a patch and install it yourself. That flaw does not exist: it was invented for the campaign. The file on offer is the hack.
The staging is restrained, which is exactly what makes it work: administrative tone, a credible-sounding flaw name, measured urgency rather than panic, a single download button. This is nothing like crude banking phishing, and experienced merchants do click. Patchstack links the campaign to the same actor behind a December 2023 operation, which already used a fabricated vulnerability identifier.
What to check in thirty seconds
- The message names a flaw and asks you to download a file and install it yourself.
- The flaw name matches no advisory published in the vendor’s official channel.
- The link looks like the official domain, but one letter has been swapped for an accented character.
- The patch is presented as urgent while no update is offered in your own dashboard.
- The file is a plugin archive to upload by hand, not an update offered by the back office.
Why the fake site’s address looks right
The link does not point at an obviously foreign domain. It points at one built through an IDN homograph attack: a letter of the legitimate name is replaced by a visually near-identical accented character. In an address bar, at browser font size, the difference is invisible. I am not reproducing the domain here.
The practical consequence matters more than the technique: “I looked at the address and it seemed fine” is not a defence against this campaign. The only reliable check is to not follow the link at all, and to open your own dashboard, or the vendor’s site, from a bookmark you saved yourself.
I clicked the link but installed nothing
Opening the page does not compromise the shop. The mechanism Patchstack describes relies on you installing a plugin: until the file has been uploaded and activated in WordPress, the site has not been touched this way.
Two caveats, both worth acting on. If you typed administrator credentials into the page that opened, change them now and review recent back-office logins. If the file was downloaded to your computer, delete it without opening or unzipping it. Then run the checks below anyway: they take a few minutes and they settle the question, which beats living with an open one.
The published indicators, in the order I check them
-
A plugin folder with a telling name
Look in wp-content/plugins/ for a folder named authbypass-update. That is the indicator Patchstack published for this campaign. Finding it settles the matter: treat the site as compromised and move straight to incident handling.
-
A folder inside uploads
In wp-content/uploads/, look for a folder whose name starts with wp-cached-. Nothing of that shape belongs among media library files.
-
An administrator account with a random name
The plugin creates an administrator account with a random eight-character name, then hides it from the user list. The dashboard list is therefore unreliable: compare it against the actual contents of the users table in the database.
-
A scheduled task running every minute
The campaign schedules a randomly named WP-Cron task that runs every minute. Minute-level scheduling is abnormal on an ordinary shop, and it is one of the few things still visible through a WP-Cron inspection tool.
-
A plugin list you cannot trust
The malicious plugin removes itself from the plugin list. Compare what the back office shows against the real contents of wp-content/plugins/ over SFTP or through your host’s file manager.
-
What was dropped afterwards
The payload downloads webshells from known families (P.A.S.-Fork, p0wny, WSO) and sends credentials and site information to remote servers. If any earlier indicator is present, assume every credential has leaked and rotate them all: WordPress administrators, FTP/SFTP, database, hosting account.
The legitimate channel, and its limits
For a free plugin, an update arrives in the WordPress updates screen. For a paid one, it arrives through your account with the vendor, or automatically via the licence key registered on the site. There is no third route: no attachment, no archive sent by email, no direct download link in an unsolicited message.
That channel is not infallible either, and I would rather say so than sell a tidier rule. In June 2026, ShapedPlugin’s build and distribution infrastructure was compromised: several Pro versions were shipped with malicious code through the vendor’s own legitimate channel, with remediation starting on 16 June 2026 and publication on 22 June 2026. Only Pro versions were affected; the free versions on the WordPress.org repository were not. The lesson is not to distrust the official channel, but that watching your site’s files stays worthwhile even when you have done nothing unusual.
If any indicator is present
-
What to do within two hours
The order of operations right after discovering a compromise.
-
Checking whether my site is compromised
The full review, beyond this campaign’s specific indicators.
-
My WordPress site has been hacked
Handling a WordPress or WooCommerce site that is already compromised.
-
Admin passwords and shared access
Which credentials to rotate, and in what order, after a leak.
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.